Labour Day Special Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bigdisc65

Newly Released CompTIA CS0-001 Exam PDF

Page: 6 / 16
Question 24

A company provides wireless connectivity to the internal network from all physical locations for company-owned devices. Users were able to connect the day before, but now all users have reported that when they connect to an access point in the conference room, they cannot access company resources. Which of the following BEST describes the cause of the problem?

Options:

A.

The access point is blocking access by MAC address. Disable MAC address filtering.

B.

The network is not available. Escalate the issue to network support.

C.

Expired DNS entries on users’ devices. Request the affected users perform a DNS flush.

D.

The access point is a rogue device. Follow incident response procedures.

Question 25

A software engineer has resigned and given two weeks' notice. The organization is concerned the engineer may have taken proprietary code. Which of me following will BEST help the security analysis to determine IT any code has been exfilltrated?

Options:

A.

Terminate and immediately escort the engineer out of the building

B.

Develop a timeline of the engineer's system and network activity.

C.

Investigate when projects were checked out of me code repository by the engineer.

D.

Dump the contents of RAM from the engineers workstation and review.

Question 26

An analyst identifies multiple instances of node-to-node communication between several endpoints within the 10.200.2.0/24 network and a user machine at the IP address 10.200.2.5. This user machine at the IP address 10.200.2.5 is also identified as initiating outbound communication during atypical business hours with several IP addresses that have recently appeared on threat feeds.

Which of the following can be inferred from this activity?

Options:

A.

10.200.2.0/24 is infected with ransomware.

B.

10.200.2.0/24 is not routable address space.

C.

10.200.2.5 is a rogue endpoint.

D.

10.200.2.5 is exfiltrating data.

Question 27

An alert is issued from the SIEM that indicates a large number of failed logins for the same account name on one of the application servers starting at 10:20 a.m. No other significant failed login activity is detected. Using Splunk to search for activity pertaining to that account name, a security analyst finds the account has been authenticating successfully for some time and started to fail this morning. The account is attempting to authenticate from an internal server that is running a database to an application server. No other security activity is detected on the network. The analyst discovers the account owner is a developer who no longer works for the company. Which of the following is the MOST likely reason for the failed login attempts for that account?

Options:

A.

The account that is failing to authenticate has not been maintained, and the company password change policy time frame has been reached for that account

B.

The host-based firewall is blocking port 389 LDAP communication, preventing the login credentials from being received by the application server

C.

The license for the application has expired, and the failed logins will continue to occur until a new license key is installed on the application

D.

A successful malware attack has provided someone access to the network, and failed login attempts are an indication of an attempt to privilege access to the application

Page: 6 / 16
Exam Code: CS0-001
Exam Name: CompTIA CSA+ Certification Exam
Last Update: Apr 14, 2023
Questions: 455
CS0-001 pdf

CS0-001 PDF

$28  $80
CS0-001 Engine

CS0-001 Testing Engine

$33.25  $95
CS0-001 PDF + Engine

CS0-001 PDF + Testing Engine

$45.5  $130